|
|
 |
SECURITY
TRACK |
 |
|
|
|
|
| CCIE - Security Class
|
|
|
|
"Until You Pass! Risk-Free Guarantee"
|
NO. |
COURSE |
INSTRUTOR |
THEORY CLASS |
LAB TIME |
VALID |
PRICE |
|
111 |
CCIE-R/S |
David |
150 Days * 6 hours |
150 Days * 6 hours |
365 Days |
$9888 |
|
112 |
CCIE-SP |
Windy |
150 Days * 6 hours |
150 Days * 6 hours |
365 Days |
$9888 |
|
113 |
CCIE-SECURITY |
ALBERT |
150 Days * 6 hours |
150 Days * 6 hours |
365 Days |
$13888 |
|
114 |
CCIE-VOICE |
Meng |
150 Days * 6 hours |
150 Days * 6 hours |
365 Days |
$13888 |
CCIE Introduction
Cisco Certified Internetwork Expert (CCIE) is the most rigorous of Cisco's Career Certifications and identifies the upper echelon of networking experts worldwide.
This course is led by a double CCIE instructor, who is holding Routing and Switching Security CCIE with more than 10 years Internetworking experience.
Course Content
- Course duration is 300 days. If the class gets behind, class hours may be greatly extended on some days.
- This course is specifically designed to prepare students to pass the CCIE Security Lab Exam.
- To ensure that all concepts are completely understood, each student will receive dedicated instructor mentoring as needed.
- Each student will be given telnet access to Rack for the duration of the class.
- Our racks are the same as Ciscos. Thus, students will be able to familiarize themselves with the equipment before taking the exam.
- Students will receive a copy of the course material used in the class.
- Our courseware and hardware have been updated to reflect the current content of the CCIE Lab Exam.
- This class is intense and very fast paced.
- Please try and work through as many of the labs as possible before you attend class. The better prepared you are for the class, the more you will get out of it.
- Our classes have a very high success rate, provided that you come prepared.
- GUARANTEE! "Until You Pass!" Risk-Free Guarantee
COURSE OBJECTIVES
After completing this course, students will gain competency in the following topics:
Implementing secure networks using Cisco ASA Firewall
- perform basic firewall initialization
- configure device management
- configure address translation (nat, global, static)
- configure ACLs
- configure IP routing
- configure objective groups
- configure VLANs
- configure filtering
- configure failover
- configure layer 2 transparent firewall
- configure security context (virtual firewall)
- configure modular policy framework
- configure application-aware inspection
- configure high availability solutions
- configure QoS policies
Implementing Secure Networks using Cisco IOS Firewall
- conifgure CBAC
- configure zone-based firewall
- configure audit
- configure auth proxy
- configure PAM
- configure access control
- configure performance routing
- configure advanced QoS firewall features
Implementing secure network using Cisco VPN solution
- configure IPsec LAN-toLAN (IOS/ASA)
- configure SSL VPN (IOS/ASA)
- configure dynamic multipoint VPN (DMVPN)
- configure Group Encryptied Transport (GET) VPN
- configure easy VPN (IOS/ASA)
- configure CA (PKI)
- configure remote access VPN
- configure clientless WebVPN
- configure AnyConnect VPN
- configure Xauth, Split-tunnel, RRI, NAT-T
- configure High Availability
- configure QOS for VPN
- confdigure GRE, mGRE
- configure advanced Cisco VPN features
Configure Cisco IPS to mitigate network threat
- configure IPS 4200 series Sensor Applicance
- Initialize the sensor appliance
- configure sensor appliance management
- configure security policies
- configure virtual sensors on the sensor appliance
- configure promiscous and inline monitoring on the sensor appliance
- configure and tune signatures aon the sensor appliance
- configure custom signatures on the sensor appliance
- configure blocking on the sensor appliance
- configure TCP resets on the sensor appliance
- configure rate limiting on the sensor appliance
- use IDM to configure the sensor appliance
- configure event actions on the sensor appliance
- configure advanced features on the sensor appliance
- configure and tune cisco IOS IPS
- configure SPAN & RSPAN on cisco switches
Implementing Identity Management
- configure RADIUS and TACACS+ security protocols
- configure LDAP
- Configure cisco Secure ACS
- configure Certificate-based authentication
- configure proxy authentication
- configure 802.1X
- configure advanced identify management features
- configure Cisco NAC Framework
Implementing control plane and management plane security
- implementing routing plane security features (protocol authentication, route filtering
- configure control plane policing
- configure CP protection and management protection
- configure broadcastcontrol and switchport security
- configure additional CPU protection mechanisms (options drop, logging interval)
- disable unnecessary services
- control device access (telnet, HTTP, SSH, Privilege Levels)
- configure SNMP, Syslog, AAA, NTP
- configure service authentication (FTP, telnet, HTTP, other)
- configure RADIUS and TACACS+ Security Protocols
- Configure device management and security
- Router and PIX configuration
Configure Advanced Security
- Configure mitigation techniques to respond to network attacks
- configure packet marking techniques
- implement security RFCs (RFC 1918/3330, RFC 2827/3704)
- Configure Black Hole and Sink Hole solutions
- configure RTBH filtering (Remote Triggered Black Hole)
- configure traffic filtering using access-lists
- configure IOS NAT
- configure TCP intercept
- configure uRPF
- configure CAR
- configure NBAR
- configure NetFlow
- configure Anti-spoofing solutions
- configure policing
- configure and utilize packet captures
- configure transit traffic control and congestion management
- configure Cisco catalyst advanced security features
- Cisco Secure Access Control Server (CSACS)
Identify and Mitigate Network Attacks
- Identify and protect against fragmentation attacks
- identifiy and protect against malicious IP option usage
- identify and protect against network reconnaissance attacks
- identify and protect against IP spoofing attacks
- identify and protect against MAC spoofing attacks
- identify and protect against ARP spoofing attacks
- identify and protect against Denial of service (DOS) attacks
- identify and protect against man-in-the-Middle attacks
- identify and protect against port redirection attacks
- identify and protect against DHCP attacks
- identify and protect against DNS attacks
- identify and protect against smurf attacks
- identify and protect against syn attacks
- identify and protect against MAC flooding attacks
- identify and protect against VLAN hopping attacks
- identify and protect against various layer 2 and layer 3 attacks
Copyright ©2007 WOLF Network Technology Inc. All rights reserved. http://www.labwolf.com | | |
|
..:. TOP |
|
|
|